authorization { deny_action = ignore no_match = deny sources = [ { type = file enable = true path = "etc/acl.conf" } ] }